Input validation vulnerability in Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress 3.3.2

The Metform Elementor Contact Form Builder plugin for WordPress is not secure in versions up to 3.3.2. This means that an unauthenticated attacker could potentially change the permalink structure of the website. This could happen if the attacker can trick a site administrator into clicking on a link. The plugin has some security measures in place, but they only work if the proper nonce is provided.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.